---
id: CVE-2026-81330
title: >-
  The C6 ear camera transmits live video to the EarVision Android application
  over unencrypted UDP streams
summary: >-
  The C6 ear camera transmits live video to the EarVision Android application
  over unencrypted UDP streams. The application manifest permits cleartext
  traffic, and captured network traffic contains reconstructable JPEG or WEBP
  video frames…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-319
vendor: Softish
product: EarVision Android application
affected:
  - earvision_android_application 1.3.1
  - c6_ear_camera 1.3.1_Code 132
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81330'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/refs/heads/develop/csaf_files/VA/white/2026/va-26-251-01.json
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-09T16:14:05.563Z'
epss: 0.00094
epssPercentile: 0.00558
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T19:14:15.696147Z'
---

## Overview

The C6 ear camera transmits live video to the EarVision Android application over unencrypted UDP streams. The application manifest permits cleartext traffic, and captured network traffic contains reconstructable JPEG or WEBP video frames transmitted over UDP. An attacker within local wireless range may capture and reconstruct the live video stream without transport encryption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
